discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A maximum-severity zero-day vulnerability in Metabase's business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access.

By Ravie Lakshmanan·Aug 8·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Image: thehackernews.com

Metabase has issued a warning about a critical zero-day flaw (CVSS 10.0) that enables unauthenticated SQL injection, leading to full admin control over instances. This allows attackers to alter configurations, steal credentials, and access sensitive data, with Metabase Cloud instances already updated and self-hosted users urged to patch immediately.

Why it matters

This story is critical for security professionals as it highlights an actively exploited zero-day in widely used business intelligence software, granting attackers complete administrative control and access to sensitive data, posing a severe risk of widespread data breaches and system compromise.

Imagine a special computer program that helps grown-ups look at lots of information, like sales numbers or customer lists. A sneaky trick, called a 'zero-day' because nobody knew about it until now, lets bad guys pretend to be the boss of this program without needing a password. Once they're the 'boss,' they can peek at all the secret information, change how the program works, or even steal important details about customers, like their names and emails. It's like someone finding a secret master key to a building that everyone thought was super secure.

Analysis

The discovery and active exploitation of a zero-day vulnerability in Metabase's business intelligence platform underscore the persistent and evolving threat landscape facing organizations. This particular flaw, rated with a maximum CVSS score of 10.0, is exceptionally dangerous because it allows an unauthenticated remote attacker to achieve full administrator access through SQL injection. Such a high-severity vulnerability, especially one exploited in the wild before a public CVE identifier was assigned, represents a significant challenge for defenders who must react swiftly to protect their systems.

Metabase Cloud

Metabase's proactive response to the zero-day, particularly concerning its cloud offerings, demonstrates a critical aspect of modern cybersecurity incident management. The company confirmed that its Metabase Cloud instances were attacked using this unknown vulnerability, but importantly, these instances have already been updated to the latest secure versions. This rapid patching for cloud-hosted services is a significant advantage, as it automatically protects a segment of their user base without requiring direct action from individual customers. However, the incident still serves as a stark reminder that even managed services are not immune to sophisticated zero-day attacks, necessitating continuous vigilance and robust security practices from providers.

Framework

The impact of this zero-day is concretely illustrated by the compromise of Framework, a PC manufacturer. According to reports, Framework alerted its customers that personal data, including names, login IPs, addresses, phone numbers, and emails, was accessed during the hack. While Framework noted that no order or payment information was compromised, the breach of personal identifiable information (PII) is still a serious concern, potentially leading to phishing attacks or identity theft for affected individuals. This incident highlights how a vulnerability in a third-party tool like Metabase can have direct and far-reaching consequences for an organization's customers, emphasizing the interconnectedness of supply chain security.

CVE-2023-38646

This current zero-day is not Metabase's first encounter with a critical security flaw. Exactly three years prior, Metabase addressed another "extremely severe" vulnerability, CVE-2023-38646, which carried a CVSS score of 9.8. That flaw could have led to pre-authenticated remote code execution on affected installations, demonstrating a recurring pattern of high-impact security issues within the software. The recurrence of such severe vulnerabilities suggests a need for continuous improvement in Metabase's secure development lifecycle and security auditing processes. For users, it reinforces the importance of maintaining a rigorous patching schedule and staying informed about security advisories from all software vendors.

Key points

  • A maximum-severity zero-day vulnerability (CVSS 10.0) in Metabase is being actively exploited in the wild.
  • The flaw allows unauthenticated remote attackers to inject SQL and gain administrator access to Metabase instances.
  • Compromised instances enable attackers to change configurations, steal database credentials, and access connected data.
  • Metabase Cloud instances have been updated; self-hosted users must apply patches immediately (versions x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5).
  • PC maker Framework was affected, with customer names, login IPs, addresses, phone numbers, and emails accessed.
  • Indicators of Compromise (IoCs) involve specific POST and GET requests to Metabase API endpoints.
The Upside

Metabase has swiftly released patches for the vulnerability, and its cloud instances have already been updated, mitigating immediate risks for a significant portion of its user base. The provision of clear indicators of compromise and temporary workarounds empowers self-hosted users to quickly identify and address potential breaches, limiting the overall impact of the zero-day.

The Downside

Despite the available patches, self-hosted Metabase users who delay applying updates remain highly vulnerable to exploitation, potentially leading to widespread data breaches and unauthorized access. Attackers who have already gained administrator access could leverage stolen credentials to pivot to other systems, escalating the initial compromise into more severe and prolonged security incidents.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityzero-dayvulnerabilitydata-breachsoftware-securitycyber-attacksql-injection

Author

Ravie Lakshmanan

Intelligence analysis by

Gemini 2.5 Flash

Published

Aug 8, 2026

Source

thehackernews.com

Share

Topics

securityzero-dayvulnerabilitydata-breachsoftware-securitycyber-attacksql-injection

Related

More from this desk

Aug 8·bleepingcomputer.com

Hackers Exploit TrueConf Servers to Deploy Malicious Backdoors

Head Mare hackers exploit TrueConf servers to inject malicious client installers with backdoors, compromising Russian organizations in various sectors.

Aug 8·wired.com

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety pitched a plan to collect license plate data from dashcams in Uber, Lyft, and delivery drivers' vehicles. The company also gave ICE and Customs and Border Protection direct camera access through a pilot program.

Aug 8·wired.com

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researcher Cory Solovewicz has been receiving thousands of unwanted emails containing sensitive information from companies and organizations. He has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access t…

Aug 8·thehackernews.com

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms found that Atlassian's Rovo assistant can be tricked into sending Jira and Confluence data to attackers. The firms used different routes to demonstrate the vulnerability, with one route confirmed closed. The issue leaves customers without a patch to app…